VULNERABILITY INTELLIGENCE
CVE-2011-4566
CVSS score6.4 MEDIUM
EPSS probability9.83%
CISA KEVNot currently listed
Published2011-11-29
Last modified2026-06-16
Description
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a diffe... .